MultiversX Tracker is Live!

Yes, it is actually difficult to secure your seed.

Bitcoin Reddit

More / Bitcoin Reddit 18 Views

Really sorry to hear what happened to many Coldcard Mk3 users. You did nothing wrong.

To get the obvious out of the way, the hate Coinkite is getting right now is deserved. Firstly, there should have had a more thorough review process that would have caught the unintentional change in their seed generation method. Secondly, its leadership shouldn't have been so cocky and gatekeep-y. The adage "pride cometh before a fall" comes to mind. So this post is not a defense of Coinkite or an endorsement of Coldcard devices.

However, I feel the need to point out that it's best to assume all software has bugs, and after a career in tech I have never met any programmer or company who does not create bugs. Today it was the people who used a particular generation method on a particular version of a particular device that got screwed and thankfully, my setup was not affected. But I can easily imagine other alternate scenarios. None of the following things actually happened, but to me these scenarios are easy to picture:

Imagine These Alternate Scenarios

  1. Ledger's closed-source chip firmware was cracked and funds drained. Everyone blames the fact that it wasn't source-readable (unlike COLDCARD), and blames Ledger users for trusting a company that had a data breach in the past.

  2. The Coldcard bug was that if you used dice, the dice weren't used properly and ended up creating a guessable seed, whereas the people who used machine-generated seed were safe. Everyone still blames Coinkite, but the set of victims is actually the MORE paranoid ones.

  3. There is a technical flaw or bad actor in the manufacturer of Trezor's secure element, allowing seeds to be guessed. Everyone blames Trezor for not having multiple secure elements. Should have used a COLDCARD, they say.

  4. There is a mass drain of wallets from seeds generated by Electrum or Sparrow. The offline linux box users are drained, and everyone clowns on them for not using a real hardware wallet.

  5. There was yet another hack at a semi-reputable exchange like Kraken or Gemini. Everyone clowns on the victims for not using a hardware wallet.

  6. A bug was pushed to Sparrow's send function, so that people who transacted with the latest version, regardless of key management, sent their coins to the wrong address.

  7. Regulation or corruption puts funds at bitcoin ETFs at risk of being frozen. Everyone spams "not your keys, not your coins."

Keeping Your Keys Safe is Not Simple

I hate to say that, but it's a reality the community needs to face. I write because I keep seeing comments along the lines of "f--- Coinkite, let's all move to Trezor now" or something similar. But if this fiasco has taught me anything it's that things aren't that simple. Today there is a flaw in one firmware, tomorrow it could be another by another company. Evaluating the options takes skill, and even that won't entirely save you from bad luck.

More complex setups also have risks. You could spread your money among many wallets, or have a multi-sig setup that uses multiple hardware wallets from different brands, but that increases the risk of locking yourself out if you don't do everything perfectly and remember what to do.

I wish I had an easy answer. I just want to say there are a lot of things to consider. This is why security experts talk about thinking through your risk model, rather than saying "any idiot knows to just use my favorite method or company."

submitted by /u/PoeCollector
[link] [comments]
Get BONUS $200 for FREE!

You can get bonuses upto $100 FREE BONUS when you:
πŸ’° Install these recommended apps:
πŸ’² SocialGood - 100% Crypto Back on Everyday Shopping
πŸ’² xPortal - The DeFi For The Next Billion
πŸ’² CryptoTab Browser - Lightweight, fast, and ready to mine!
πŸ’° Register on these recommended exchanges:
🟑 Binance🟑 Bitfinex🟑 Bitmart🟑 Bittrex🟑 Bitget
🟑 CoinEx🟑 Crypto.com🟑 Gate.io🟑 Huobi🟑 Kucoin.



Comments